{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ajinareader/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:jina:reader:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82638"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["reader"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Jina AI"],"content_html":"\u003cp\u003eCVE-2026-82638 is a critical server-side request forgery (SSRF) vulnerability affecting Jina AI reader. The vulnerability stems from the implementation logic of the internal request validator, which disables the private-address guard mechanism when the application detects it is not running within a Google Cloud environment. This misconfiguration allows unauthenticated actors to bypass intended network restrictions by supplying crafted, publicly resolvable hostnames that point to internal IP addresses or cloud metadata service endpoints (e.g., 169.254.169.254). An attacker can leverage this flaw to interact with internal services that lack authentication, potentially leading to unauthorized data exfiltration or internal service manipulation. Organizations deploying Jina AI reader in on-premises or non-GCP cloud environments are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to probe internal networks, retrieve sensitive cloud metadata, and access private services that are not exposed to the public internet. This bypasses network-level security controls, potentially leading to the compromise of internal credentials, environment configurations, or sensitive business data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching or updating Jina AI reader to a version that enforces the private-address guard regardless of the hosting environment. For environments where patching is not immediately feasible, implement egress filtering at the network boundary to prevent the application host from initiating connections to private address spaces (e.g., RFC1918) or sensitive metadata services. Ensure logs are reviewed for anomalous outbound requests originating from the application server that reference non-public or internal address schemes.\u003c/p\u003e\n","date_modified":"2026-08-30T15:11:04Z","date_published":"2026-08-30T15:11:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-jina-ai-ssrf/","summary":"Jina AI reader contains a server-side request forgery vulnerability caused by a missing private-address guard when deployed outside of Google Cloud, allowing unauthenticated attackers to access internal network resources.","title":"CVE-2026-82638 - SSRF Vulnerability in Jina AI Reader","url":"https://feed.craftedsignal.io/briefs/2026-08-jina-ai-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:jina:reader:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}